Spyduino: Arduino as a HID Exploiting the BadUSB Vulnerability
Evangelos Karystinos, Antonios S. Andreatos, Christos Douligeris · 2019
BadUSB is a critical vulnerability which has not yet been successfully addressed. BadUSB attacks are based on reprogramming the firmware of a USB device. This paper presents Spyduino, a properly programmed Arduino appearing as a Human Interface Device (HID), which can operate in most of the common operating systems (OSs). Spyduino exploits the BadUSB vulnerability in order to gain access to sensitive data and send information to the cloud via FTP. In this implementation, Spyduino is embedded in a USB keyboard and sends sensitive OS and user information to an FTP server without user permission. Various countermeasures are discussed and potential extensions are presented.